Access control

Access is granted per menu item. A role is built by ticking the screens it may reach, so it can be exactly as broad as the job actually is — and no broader.

  • Roles are built from the menu tree itself: every screen in the application is a tick box.
  • Assign a role to a user; change the role and everyone on it moves at once.
  • Hide whole modules — payroll, the general ledger, system settings — from people with no business in them.
  • Separate duties properly: the person who keys vouchers need not be the person who approves and posts them.
  • Each user still has their own login, language, number and date formats.
  • Users can be locked out without being deleted, so their history stays intact.
  • Administrators can see and change any role from System > Roles.

Where to find it System › Roles › Add Role  ·  HR › Employees › Add Employee

Creating a role

  1. Open System › Roles › Add Role and name it.
  2. The access control block is the whole menu tree, every screen a tick box. Everything starts ticked; untick a module to hide it entirely, or open it and untick individual screens.
  3. Save. The role list shows, per role, exactly what is disabled.
The add role screen with the menu tree as tick boxes
Add Role: the menu tree, every screen a tick box.
The Bookkeeper role open for editing with POS unticked
Bookkeeper: POS unticked, so the till never appears for anyone on this role.
Role list showing a role and the menu items it excludes
The role list shows what each one excludes.

Giving someone a login

  1. Open the employee under HR › Employees (or add one). Enter a Login and Password and pick the Role.
  2. Tick Sales if they should appear in the salesperson drop-down; tick E-mail TAN to require a code sent by email on each login.
  3. Save. They sign in with that login; their own preferences (language, formats) are under System › Preferences once they are in. To suspend someone, clear the login; their history stays.
An employee record showing the login field
Assign the role to the person on their own record.
User preferences screen
Everyone still keeps their own language and formats.

Every dataset on our hosting has this, from day one.

Create your free account or ask us about migrating